Implementation of netSystemSbinIp

This commit is contained in:
Jagger
2016-02-28 23:40:34 +01:00
parent 8dad34ae4a
commit 6218fe2336
4 changed files with 20 additions and 11 deletions

View File

@@ -24,6 +24,7 @@
#include <ctype.h>
#include <errno.h>
#include <fcntl.h>
#include <getopt.h>
#include <grp.h>
#include <limits.h>
@@ -35,7 +36,9 @@
#include <strings.h>
#include <sys/personality.h>
#include <sys/mount.h>
#include <sys/stat.h>
#include <sys/time.h>
#include <sys/types.h>
#include <unistd.h>
#include "common.h"
@@ -280,6 +283,7 @@ bool cmdlineParse(int argc, char *argv[], struct nsjconf_t * nsjconf)
.max_conns_per_ip = 0,
.tmpfs_size = 4 * (1024 * 1024),
.mount_proc = true,
.sbinip_fd = -1,
};
/* *INDENT-OFF* */
@@ -598,5 +602,9 @@ bool cmdlineParse(int argc, char *argv[], struct nsjconf_t * nsjconf)
return false;
}
if ((nsjconf->sbinip_fd = open("/sbin/ip", O_RDONLY)) == -1) {
PLOG_E("No /sbin/ip on your system. Networking support is limited");
}
return true;
}

View File

@@ -99,6 +99,7 @@ struct nsjconf_t {
unsigned int max_conns_per_ip;
size_t tmpfs_size;
bool mount_proc;
int sbinip_fd;
TAILQ_HEAD(envlist, charptr_t) envs;
TAILQ_HEAD(pidslist, pids_t) pids;
TAILQ_HEAD(mountptslist, mounts_t) mountpts;

21
net.c
View File

@@ -40,7 +40,7 @@
#include "log.h"
static bool netSystem(const char *bin, char *const *argv)
bool netSystemSbinIp(struct nsjconf_t *nsjconf, char *const *argv)
{
int pid = fork();
if (pid == -1) {
@@ -48,8 +48,8 @@ static bool netSystem(const char *bin, char *const *argv)
return false;
}
if (pid == 0) {
execv(bin, argv);
PLOG_E("execve('%s')", bin);
fexecve(nsjconf->sbinip_fd, argv, environ);
PLOG_E("fexecve('fd=%d')", nsjconf->sbinip_fd);
_exit(1);
}
@@ -60,19 +60,18 @@ static bool netSystem(const char *bin, char *const *argv)
if (WEXITSTATUS(status) == 0) {
return true;
}
LOG_W("'%s' returned with exit status: %d", bin, WEXITSTATUS(status));
LOG_W("'/sbin/ip' returned with exit status: %d", WEXITSTATUS(status));
return false;
}
if (WIFSIGNALED(status)) {
LOG_W("'%s' killed with signal: %d", bin, WTERMSIG(status));
LOG_W("'/sbin/ip' killed with signal: %d", WTERMSIG(status));
return false;
}
LOG_E("Unknown exit status for '%s' (pid=%d): %d", bin, pid, status);
LOG_E("Unknown exit status for '/sbin/ip' (pid=%d): %d", pid, status);
kill(pid, SIGKILL);
}
}
#define SBIN_IP_PATH "/sbin/ip"
bool netCloneMacVtapAndNS(struct nsjconf_t * nsjconf, int pid)
{
if (nsjconf->iface == NULL) {
@@ -83,8 +82,8 @@ bool netCloneMacVtapAndNS(struct nsjconf_t * nsjconf, int pid)
snprintf(iface, sizeof(iface), "NS.TAP.%d", pid);
char *const argv_add[] =
{ SBIN_IP_PATH, "link", "add", "link", nsjconf->iface, iface, "type", "macvtap", NULL };
if (netSystem(SBIN_IP_PATH, argv_add) == false) {
{ "ip", "link", "add", "link", nsjconf->iface, iface, "type", "macvtap", NULL };
if (netSystemSbinIp(nsjconf, argv_add) == false) {
LOG_E("Couldn't create MACVTAP interface for '%s'", nsjconf->iface);
return false;
}
@@ -92,10 +91,10 @@ bool netCloneMacVtapAndNS(struct nsjconf_t * nsjconf, int pid)
char pid_str[256];
snprintf(pid_str, sizeof(pid_str), "%d", pid);
char *const argv_netns[] =
{ SBIN_IP_PATH, "link", "set", "dev", iface, "netns", pid_str, "name", "virt.ns",
{ "ip", "link", "set", "dev", iface, "netns", pid_str, "name", "virt.ns",
NULL
};
if (netSystem(SBIN_IP_PATH, argv_netns) == false) {
if (netSystemSbinIp(nsjconf, argv_netns) == false) {
LOG_E("Couldn't put interface '%s' into NS of PID '%d'", iface, pid);
return false;
}

1
net.h
View File

@@ -26,6 +26,7 @@
#include "common.h"
bool netSystemSbinIp(struct nsjconf_t *nsjconf, char *const *argv);
bool netCloneMacVtapAndNS(struct nsjconf_t *nsjconf, int pid);
bool netLimitConns(struct nsjconf_t *nsjconf, int connsock);
int netGetRecvSocket(const char *bindhost, int port);